Missivo Privacy Policy
Last updated: 31 August 2026
Missivo is a Shopify app that generates and transmits legally required electronic invoices (EN 16931 formats such as Factur‑X, XRechnung and UBL/Peppol BIS) for business‑to‑business orders placed in a merchant’s store. This policy explains what data the app processes, why, and what happens to it.
Roles
For personal data contained in a store’s orders, the merchant is the data controller and Missivo acts as a data processor: we process order data solely to produce and deliver the invoices the merchant is legally required to issue, on the merchant’s instruction (installing and configuring the app).
Data we process
- Order data received from Shopify’s
orders/paidwebhook: buyer name, company name, billing address, email address, VAT identification number, line items, amounts and taxes. This is exactly the data an invoice legally must contain. - Merchant settings: the seller company details the merchant enters (company name, address, VAT id, IBAN), used as the issuer identity on invoices.
- Generated invoices: the produced documents and their delivery status.
Missivo does not collect analytics on buyers, does not sell or share data for advertising, and does not process payment card data of any kind.
Why we process it
Solely to (1) generate invoices in the format required by the applicable e‑invoicing mandate, (2) validate business VAT numbers against the European Commission’s VIES service, and (3) where the merchant enables it, transmit invoices through the legally required delivery networks (the Peppol network / French PDP platforms). Legal bases: performance of the app contract with the merchant and the merchant’s own legal obligations (GDPR Art. 6(1)(b) and (c)).
Subprocessors
- Fly.io — application hosting and database, EU region (Paris).
- B2Brouter (Invinet Sistemes, ES) — registered Peppol access point and French PDP used to transmit invoices, only when transmission is enabled by the merchant.
- European Commission VIES — VAT number validity checks (the VAT number only; no other personal data is sent).
Retention and deletion
- Invoice records are retained while the app is installed, so merchants can access their legally required documents.
- When a merchant uninstalls the app, all of the store’s data — settings, order payloads, invoice records — is deleted following Shopify’s
shop/redactnotice (sent 48 hours after uninstall). - Customer erasure requests (
customers/redact) remove stored personal data beyond what the invoice itself must legally contain; issued invoices are retained because statutory tax retention obligations override erasure (GDPR Art. 17(3)(b)).
Security
Data is encrypted in transit (TLS) and at rest, hosted exclusively in the EU, with access limited to what the app needs to function. API credentials are stored as platform secrets, never in code.
Your rights & contact
Buyers should direct access/erasure requests to the merchant they purchased from (the controller); we support merchants in fulfilling them via the mechanisms above. Questions about this policy: support@missivo.app.